CVE-2026-28381: Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT
Published Jun 22, 2026
·Updated
The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.
Affected Software
2 affected components
Grafana Grafana Snowflake datasource
Grafana Snowflake>=1.14.7<=1.14.12
Event History
Jun 22, 2026
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
DescriptionSeverity
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-28381?
The severity of CVE-2026-28381 is critical with a score of 9.6.
2
How do I fix CVE-2026-28381?
To fix CVE-2026-28381, restrict access to the Snowflake datasource to trusted users only.
3
What kind of vulnerabilities does CVE-2026-28381 represent?
CVE-2026-28381 represents a local file read/write vulnerability that can lead to privilege escalation.
4
What systems are affected by CVE-2026-28381?
CVE-2026-28381 affects systems utilizing the Snowflake datasource with Grafana.
5
What functionalities are exploited in CVE-2026-28381?
CVE-2026-28381 exploits the GET/PUT command functionalities of the Snowflake datasource to manipulate files.